• caglararli@hotmail.com
  • 05386281520

CVE-2023-47116 | HumanSignal label-studio up to 1.10.x Environment Variable SSRF_PROTECTION_ENABLED server-side request forgery (GHSA-p59w-9gqw-wj8r)

Çağlar Arlı      -    15 Views

CVE-2023-47116 | HumanSignal label-studio up to 1.10.x Environment Variable SSRF_PROTECTION_ENABLED server-side request forgery (GHSA-p59w-9gqw-wj8r)

A vulnerability, which was classified as critical, has been found in HumanSignal label-studio up to 1.10.x. Affected by this issue is some unknown functionality of the component Environment Variable Handler. The manipulation of the argument SSRF_PROTECTION_ENABLED leads to server-side request forgery. This vulnerability is handled as CVE-2023-47116. The attack may be launched remotely. There is no exploit available. It is recommended to upgrade the affected component.